An Image Upload API allows a mobile application such as React Native to send an image to a PHP REST API. The API validates the image, generates a safe filename, stores it on the server, and returns information about the uploaded image.
An Image Upload API is an API endpoint that receives an image from a client application and stores or processes it on the server.
React Native
↓
Select Image
↓
FormData
↓
PHP REST API
↓
Validate Image
↓
Save Image
↓
JSON Response
Many mobile applications need to upload images for:
User Selects Image
↓
React Native
↓
FormData
↓
POST Request
↓
PHP API
↓
Image Validation
↓
Generate Filename
↓
Save Image
↓
JSON Response
The POST method is commonly used for image uploads.
POST
/api/image_upload.php
The request normally uses
multipart/form-data.
Images are commonly sent using multipart form data.
Content-Type:
multipart/form-data
This format allows a request to contain an image along with other form fields.
PHP provides uploaded image information through the
$_FILES superglobal.
$image =
$_FILES['image'];
Important values include:
nametypetmp_nameerrorsizeif (
!isset($_FILES['image'])
) {
http_response_code(400);
echo json_encode([
"success" => false,
"message" =>
"Image is required"
]);
exit;
}
Always check the expected upload field before processing the image.
if (
$_FILES['image']['error']
!== UPLOAD_ERR_OK
) {
http_response_code(400);
echo json_encode([
"success" => false,
"message" =>
"Image upload failed"
]);
exit;
}
Checking the upload error prevents the API from processing an unsuccessful upload.
Images can consume significant storage space. Define a maximum size.
$maxSize =
5 * 1024 * 1024;
if (
$_FILES['image']['size']
> $maxSize
) {
http_response_code(422);
echo json_encode([
"success" => false,
"message" =>
"Image is too large"
]);
exit;
}
The example allows images up to 5 MB.
$extension =
strtolower(
pathinfo(
$_FILES['image']['name'],
PATHINFO_EXTENSION
)
);
This extracts the extension from the original filename.
The extension should not be trusted as the only security check.
Only allow image types that your application actually needs.
$allowedExtensions = [
'jpg',
'jpeg',
'png',
'webp'
];
if (
!in_array(
$extension,
$allowedExtensions,
true
)
) {
http_response_code(422);
echo json_encode([
"success" => false,
"message" =>
"Image type not allowed"
]);
exit;
}
A filename extension can be changed by the client.
photo.exe
photo.jpg
Changing the extension does not necessarily change the actual contents of the file.
Therefore, use additional validation such as MIME detection and image processing checks where appropriate.
$finfo = new finfo(
FILEINFO_MIME_TYPE
);
$mimeType =
$finfo->file(
$_FILES['image']['tmp_name']
);
This allows the server to inspect the uploaded file rather than relying only on the client-provided MIME type.
$allowedMimeTypes = [
'image/jpeg',
'image/png',
'image/webp'
];
if (
!in_array(
$mimeType,
$allowedMimeTypes,
true
)
) {
http_response_code(422);
echo json_encode([
"success" => false,
"message" =>
"Invalid image type"
]);
exit;
}
PHP can inspect image information using
getimagesize().
$imageInfo =
getimagesize(
$_FILES['image']['tmp_name']
);
if ($imageInfo === false) {
http_response_code(422);
echo json_encode([
"success" => false,
"message" =>
"Invalid image"
]);
exit;
}
This provides another useful validation layer for image uploads.
Never depend on the original filename as the permanent server filename.
$newName =
bin2hex(
random_bytes(16)
)
. '.'
. $extension;
A unique generated name helps prevent filename collisions.
$uploadDir =
__DIR__ . '/uploads/images/';
if (!is_dir($uploadDir)) {
mkdir(
$uploadDir,
0755,
true
);
}
Keep uploaded images in a dedicated directory.
$destination =
$uploadDir . $newName;
if (
!move_uploaded_file(
$_FILES['image']['tmp_name'],
$destination
)
) {
http_response_code(500);
echo json_encode([
"success" => false,
"message" =>
"Unable to save image"
]);
exit;
}
<?php
header(
"Content-Type: application/json"
);
if (
!isset($_FILES['image'])
) {
http_response_code(400);
echo json_encode([
"success" => false,
"message" =>
"Image is required"
]);
exit;
}
$image =
$_FILES['image'];
if (
$image['error']
!== UPLOAD_ERR_OK
) {
http_response_code(400);
echo json_encode([
"success" => false,
"message" =>
"Image upload failed"
]);
exit;
}
$maxSize =
5 * 1024 * 1024;
if ($image['size'] > $maxSize) {
http_response_code(422);
echo json_encode([
"success" => false,
"message" =>
"Image is too large"
]);
exit;
}
$extension =
strtolower(
pathinfo(
$image['name'],
PATHINFO_EXTENSION
)
);
$allowedExtensions = [
'jpg',
'jpeg',
'png',
'webp'
];
if (
!in_array(
$extension,
$allowedExtensions,
true
)
) {
http_response_code(422);
echo json_encode([
"success" => false,
"message" =>
"Image type not allowed"
]);
exit;
}
$finfo = new finfo(
FILEINFO_MIME_TYPE
);
$mimeType =
$finfo->file(
$image['tmp_name']
);
$allowedMimeTypes = [
'image/jpeg',
'image/png',
'image/webp'
];
if (
!in_array(
$mimeType,
$allowedMimeTypes,
true
)
) {
http_response_code(422);
echo json_encode([
"success" => false,
"message" =>
"Invalid image type"
]);
exit;
}
$imageInfo =
getimagesize(
$image['tmp_name']
);
if ($imageInfo === false) {
http_response_code(422);
echo json_encode([
"success" => false,
"message" =>
"Invalid image"
]);
exit;
}
$newName =
bin2hex(
random_bytes(16)
)
. '.'
. $extension;
$uploadDir =
__DIR__ . '/uploads/images/';
if (!is_dir($uploadDir)) {
mkdir(
$uploadDir,
0755,
true
);
}
$destination =
$uploadDir . $newName;
if (
!move_uploaded_file(
$image['tmp_name'],
$destination
)
) {
http_response_code(500);
echo json_encode([
"success" => false,
"message" =>
"Unable to save image"
]);
exit;
}
echo json_encode([
"success" => true,
"message" =>
"Image uploaded successfully",
"filename" =>
$newName,
"mime_type" =>
$mimeType
]);
?>
An image upload API can receive normal form fields together with the image.
$studentId =
$_POST['student_id']
?? '';
$caption =
$_POST['caption']
?? '';
$image =
$_FILES['image']
?? null;
For example, a student profile API can receive a student ID and profile photo in the same request.
Usually, the image file is stored on the server while its metadata is stored in MySQL.
CREATE TABLE student_images (
id INT AUTO_INCREMENT PRIMARY KEY,
student_id INT NOT NULL,
filename VARCHAR(255) NOT NULL,
original_name VARCHAR(255) NOT NULL,
mime_type VARCHAR(100) NOT NULL,
file_size INT NOT NULL,
created_at TIMESTAMP
DEFAULT CURRENT_TIMESTAMP
);
$stmt = $pdo->prepare(
"INSERT INTO student_images
(
student_id,
filename,
original_name,
mime_type,
file_size
)
VALUES (?, ?, ?, ?, ?)"
);
$stmt->execute([
$studentId,
$newName,
$image['name'],
$mimeType,
$image['size']
]);
Use prepared statements when storing image information in the database.
React Native can send an image to the API using FormData.
const formData =
new FormData();
formData.append(
"image",
{
uri: image.uri,
name: image.fileName
|| "photo.jpg",
type: image.mimeType
|| "image/jpeg"
}
);
The exact image object depends on the image picker library used in the project.
const response =
await fetch(
"https://example.com/api/image_upload.php",
{
method: "POST",
body: formData
}
);
const result =
await response.json();
console.log(result);
The server processes the multipart request and returns a JSON response.
If the image belongs to a logged-in user, protect the endpoint with authentication.
Authorization:
Bearer YOUR_JWT_TOKEN
The PHP API should verify the token before saving the image and associating it with the authenticated user.
JWT
↓
Identify User
↓
Validate Image
↓
Save Image
↓
Save Metadata
getimagesize() where appropriate.You can test an image upload API using Postman.
POST
http://localhost/api/image_upload.php
Body
↓
form-data
Key: image
Type: File
↓
Select Image
You can also add fields such as
student_id or caption.
React Native
↓
Image Picker
↓
Selected Image
↓
FormData
↓
POST Request
↓
JWT Authentication
↓
PHP REST API
↓
Size Validation
↓
MIME Validation
↓
Image Validation
↓
Generate Filename
↓
Save Image
↓
Save Database Metadata
↓
JSON Response
↓
React Native
A secure image upload API should receive an image through multipart form data, validate the upload, check its size and type, generate a unique filename, store the image safely, optionally save metadata in MySQL, and return a JSON response.
Select Image
↓
Validate
↓
Generate Safe Name
↓
Save Image
↓
Save Metadata
↓
Return JSON
This pattern can be used for profile photos, student images, product images, certificates, and other image-based features in mobile applications.
$_FILES.getimagesize() can be used to verify image data.move_uploaded_file() to save uploaded images.Question: Which PHP function can be used to check whether an uploaded file contains valid image information?